mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()
Summary
| CVE | CVE-2026-89756 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-11 20:20:06 UTC |
| Updated | 2026-09-14 13:19:24 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch() migrate_pages_batch() unmaps each folio before moving it, and every unmap runs the mmu_notifier invalidate callbacks. On KVM hosts try_to_migrate() ends up in kvm_mmu_notifier_invalidate_range_start() -> tdp_mmu_zap_leafs(), which is expensive, so unmapping a large batch keeps the CPU busy for a long time. The loop already calls cond_resched(), but on PREEMPTION kernels that is a no-op, and involuntary preemption is not a Tasks-RCU quiescent state. A long batch therefore never reports a quiescent state, and the migrating task (e.g. kcompactd) becomes a Tasks-RCU holdout, stalling the Tasks-RCU grace period for minutes, which is common at Meta fleet: INFO: rcu_tasks detected stalls on tasks: 0000000055349ecc: .. nvcsw: 1157401/1157401 holdout: 1 idle_cpu: -1/56 task:kcompactd0 state:R running task Call Trace: tdp_mmu_zap_leafs tdp_mmu_next_root gfn_to_pfn_cache_invalidate_start kvm_mmu_notifier_invalidate_range_start __mmu_notifier_invalidate_range_start try_to_migrate_one try_to_migrate migrate_pages_batch migrate_pages compact_zone compact_node kcompactd kthread Use cond_resched_tasks_rcu_qs() so a quiescent state is reported even when cond_resched() does nothing. This has also been discussed at [1] |
Risk And Classification
EPSS: 0.001860000 probability, percentile 0.083720000 (date 2026-09-14)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 8315f42295d2667a7f942f154b73a86fd7cb2227 8c6d63d434ebb85c6cf3dac1e70a171b183c6614 git | Not specified |
| CNA | Linux | Linux | affected 8315f42295d2667a7f942f154b73a86fd7cb2227 4757542649af56d894e25e30f57cd497dffad53f git | Not specified |
| CNA | Linux | Linux | affected 8315f42295d2667a7f942f154b73a86fd7cb2227 4996a7bc01ef35570664854dac2530c604981039 git | Not specified |
| CNA | Linux | Linux | affected 8315f42295d2667a7f942f154b73a86fd7cb2227 5dc0daff0341c6baba19c38f47d299ac831d7e99 git | Not specified |
| CNA | Linux | Linux | affected 8315f42295d2667a7f942f154b73a86fd7cb2227 66734981b4d3c105223a13c827c9c73be18d91ad git | Not specified |
| CNA | Linux | Linux | affected 8315f42295d2667a7f942f154b73a86fd7cb2227 efe8f86c0916f0f74eea74ae21a3b37f728c6bad git | Not specified |
| CNA | Linux | Linux | affected 3.18 | Not specified |
| CNA | Linux | Linux | unaffected 3.18 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.188 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.157 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.109 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.50 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.4 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/efe8f86c0916f0f74eea74ae21a3b37f728c6bad | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/8c6d63d434ebb85c6cf3dac1e70a171b183c6614 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/4757542649af56d894e25e30f57cd497dffad53f | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/66734981b4d3c105223a13c827c9c73be18d91ad | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/5dc0daff0341c6baba19c38f47d299ac831d7e99 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/4996a7bc01ef35570664854dac2530c604981039 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.